Correction d'oracle de chiffrement
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows Vista
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\Délégation d’informations d’identification Description
Correction d'oracle de chiffrement Ce paramètre de stratégie s'applique aux applications qui utilisent le composant CredSSP (par exemple : Connexion Bureau à distance). Certaines versions du protocole CredSSP sont vulnérables à une attaque de l'oracle de chiffrement à l'encontre du client. Cette stratégie contrôle la compatibilité avec des clients et serveurs vulnérables. Cette stratégie vous permet de définir le niveau de protection souhaité pour la vulnérabilité de l'oracle de chiffrement. Si vous activez ce paramètre de stratégie, la prise en charge de la version CredSSP est sélectionnée en fonction des options suivantes : Forcer les clients mis à jour : les applications clientes qui utilisent CredSSP ne peuvent pas avoir recours aux versions non sécurisées et les services qui utilisent CredSSP n'acceptent pas les clients non corrigés. Remarque : ce paramètre ne doit pas être déployé tant que tous les hôtes distants ne prennent pas en charge la dernière version. Atténué : les applications clientes qui utilisent CredSSP ne peuvent pas avoir recours à la version non sécurisée, mais les services qui utilisent CredSSP acceptent les clients non corrigés. Consultez le lien ci-dessous pour obtenir des informations importantes sur le risque représenté par des clients non corrigés restants. Vulnérable : les applications clientes qui utilisent CredSSP exposent les serveurs distants aux attaques en prenant en charge le recours à des versions non sécurisées et les services qui utilisent CredSSP acceptent les clients non corrigés. Pour plus d'informations sur la vulnérabilité et les conditions de maintenance pour la protection, voir https://go.microsoft.com/fwlink/?linkid=866660
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_CredSsp/AllowEncryptionOracle Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Correction d'oracle de chiffrement
; State: Enabled
; Supported on: Au minimum Windows Vista
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters]
"AllowEncryptionOracle"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowEncryptionOracle' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_CredSsp/AllowEncryptionOracle
Data type: String
Value:
<enabled/>
<data id="AllowEncryptionOracleDrop" value="1"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters' -Name 'AllowEncryptionOracle' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowEncryptionOracle' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters' -Name 'AllowEncryptionOracle' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Correction d'oracle de chiffrement
# State: Enabled
# Supported on: Au minimum Windows Vista
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowEncryptionOracle' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).